Research is the last sector in Annex 2 to OUG 155/2024. Medium-sized and large organisations are important entities, with standard scores of 125 and 187.5, so the important level. The definition is restrictive, though: what matters is the purpose of the research, not just the fact that you do research.

Who is covered by NIS2 in research

Annex 2 to OUG 155/2024 takes over the list and definition in the NIS2 Directive. What counts is the entity’s primary goal. In practice, it covers:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law62.5basic34 controls, threshold 2.5
Mediumimportant125important133 controls, threshold 3
Largeimportant187.5important133 controls, threshold 3

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Find your level and maturity score in a few minutes. The calculator opens with the “Research” sector already selected; you choose the size and answer 12 questions.

Calculate the level for research

Which systems are assessed in a research organisation

In a research organisation, the value lies in data and results. The assessment usually covers:

Europe’s supercomputers, May 2020

In May 2020, several high-performance computing centres in Europe were taken offline after intrusions: ARCHER, at the University of Edinburgh, several clusters in Germany, including at the Jülich Research Centre, and the Swiss centre CSCS. The attackers installed cryptocurrency miners, and the German centres reset users’ SSH passwords.

Research has a different risk profile from other sectors: many external users, international collaborations, old laboratory equipment and data that is valuable for industrial espionage. Often the goal is not to stop the work but to use the resources or steal the results.

For NIS2, this shifts the focus to identities and data: personal accounts for every collaborator, multi-factor authentication for remote access, accounts closed at the end of projects and classification of project data, so that you know what needs better protection.

What comes next

How TRU helps

In research, protecting results matters as much as availability. We start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a university covered by NIS2?

Not as a research organisation: the definition excludes education institutions, even if they do research.

We have an R&D department. Are we covered under research?

As a rule, no: what counts is the entity’s primary goal. A factory with an R&D department is classified by its main activity, for example under manufacturing.

We do basic research with no commercial aim. Are we covered?

Not on this basis. The definition targets applied research and experimental development with a view to commercial exploitation of the results.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Security Affairs, supercomputers hacked across Europe, 17 May 2020.